Total
1045 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-1000844 | 1 Squareup | 1 Retrofit | 2019-07-01 | 6.4 MEDIUM | 9.1 CRITICAL |
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437. | |||||
CVE-2018-18406 | 1 Tufin | 2 Securetrack, Tufinos | 2019-06-24 | 6.5 MEDIUM | 9.9 CRITICAL |
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users. | |||||
CVE-2019-11392 | 1 Dotnetblogengine | 1 Blogengine.net | 2019-06-23 | 5.0 MEDIUM | 7.5 HIGH |
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. | |||||
CVE-2019-10718 | 1 Dotnetblogengine | 1 Blogengine.net | 2019-06-23 | 5.0 MEDIUM | 7.5 HIGH |
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | |||||
CVE-2018-15506 | 1 Bubblesoftapps | 1 Bubbleupnp | 2019-06-21 | 7.5 HIGH | 9.8 CRITICAL |
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running BubbleUPnP, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack the cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains. | |||||
CVE-2019-12154 | 1 Realobjects | 1 Pdfreactor | 2019-06-13 | 6.4 MEDIUM | 9.1 CRITICAL |
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced resources, leading to disclosure of local file contents and/or denial of service conditions. | |||||
CVE-2018-20160 | 1 Synacor | 1 Zimbra Collaboration Suite | 2019-05-30 | 7.5 HIGH | 9.8 CRITICAL |
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XXE attacks, as demonstrated by a crafted XML request to mailboxd. | |||||
CVE-2018-8940 | 1 Enghouse | 1 Contact Center\ | 2019-05-15 | 7.5 HIGH | 9.8 CRITICAL |
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, allowing an attacker to upload a malicious XML file and reference it in the URL of the application, forcing the application to load and parse the malicious XML file, aka an XXE issue. | |||||
CVE-2018-20664 | 1 Zohocorp | 1 Manageengine Adselfservice Plus | 2019-05-13 | 7.5 HIGH | 9.8 CRITICAL |
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. | |||||
CVE-2019-7442 | 1 Cyberark | 1 Enterprise Password Vault | 2019-05-10 | 7.5 HIGH | 9.8 CRITICAL |
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attackers to read arbitrary files or potentially bypass authentication via a crafted DTD in the SAML authentication system. | |||||
CVE-2018-14485 | 1 Blogengine | 1 Blogengine.net | 2019-05-08 | 7.5 HIGH | 9.8 CRITICAL |
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. | |||||
CVE-2017-1458 | 1 Ibm | 1 Qradar Network Security | 2019-05-06 | 5.5 MEDIUM | 8.1 HIGH |
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377. | |||||
CVE-2019-11677 | 1 Zohocorp | 1 Manageengine Firewall Analyzer | 2019-05-03 | 7.5 HIGH | 9.8 CRITICAL |
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injection. | |||||
CVE-2019-11519 | 1 Nopcommerce | 1 Nopcommerce | 2019-05-01 | 4.0 MEDIUM | 4.9 MEDIUM |
Libraries/Nop.Services/Localization/LocalizationService.cs in nopCommerce through 4.10 allows XXE via the "Configurations -> Languages -> Edit Language -> Import Resources -> Upload XML file" screen. | |||||
CVE-2018-17169 | 1 Printeron | 1 Printeron | 2019-04-30 | 4.0 MEDIUM | 7.7 HIGH |
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | |||||
CVE-2014-3990 | 1 Opencart | 1 Opencart | 2019-04-25 | 7.5 HIGH | 9.8 CRITICAL |
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forgery (SSRF) attacks or possibly conduct XML External Entity (XXE) attacks and execute arbitrary code via a crafted serialized PHP object, related to the quantity parameter in an update request. | |||||
CVE-2018-17289 | 1 Kofax | 1 Front Office Server | 2019-04-19 | 4.0 MEDIUM | 6.5 MEDIUM |
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated users to read arbitrary files via crafted XML inside an imported package configuration (.ZIP file) within the Kofax/KFS/Admin/PackageService/package/upload file parameter. | |||||
CVE-2019-8999 | 1 Blackberry | 1 Unified Endpoint Management | 2019-04-19 | 5.0 MEDIUM | 7.5 HIGH |
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain read access to files on any system reachable by the UEM service account. | |||||
CVE-2019-0284 | 1 Sap | 1 Hana | 2019-04-11 | 3.6 LOW | 6.0 MEDIUM |
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attacker can call SLDREG with an XML file containing a reference to an XML External Entity (XXE). This can cause SLDREG to, for example, continuously loop, read arbitrary files and even send local files. | |||||
CVE-2019-0795 | 1 Microsoft | 8 Windows 10, Windows 7, Windows 8.1 and 5 more | 2019-04-11 | 9.3 HIGH | 8.8 HIGH |
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0790, CVE-2019-0791, CVE-2019-0792, CVE-2019-0793. |